nifi-framework-core is vulnerable to Insertion of Sensitive Information into Log File
69
Medium Risk
Affected versions of this package are vulnerable to potential exposure of sensitive information. During flow synchronization, optional debug logging of parameter context values may occur if an authorized administrator enables debug logging for framework flow synchronization. This could cause the application to log parameter names and values, which might include sensitive information depending on the flow configuration.
You are affected if you are using a version which is within vulnerability ranges
nifi-framework-core is vulnerable to Insertion of Sensitive Information into Log File in versions 1.16.0 - 1.28.0.
Upgrade the org.apache.nifi:nifi-framework-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant